CVE-2018-12022

Published

Severity

CVSS v3:
7.5 HIGH
CVSS v2:
5.1 MEDIUM

Description

An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*2.7.0 (including)2.7.9.4*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*2.8.0 (including)2.8.11.2*
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*2.9.0 (including)2.9.6*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*n/an/a9.0
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*n/an/a29
cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2:*:*:*:*:*:*:*n/an/a9.2
cpe:2.3:a:oracle:retail_merchandising_system:15.0:*:*:*:*:*:*:*n/an/a15.0
cpe:2.3:a:redhat:openshift_container_platform:3.11:*:*:*:*:*:*:*n/an/a3.11
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*n/an/a7.2.0
cpe:2.3:a:redhat:single_sign-on:7.3:*:*:*:*:*:*:*n/an/a7.3
cpe:2.3:a:redhat:jboss_brms:6.4.10:*:*:*:*:*:*:*n/an/a6.4.10
cpe:2.3:a:redhat:automation_manager:7.3.1:*:*:*:*:*:*:*n/an/a7.3.1
cpe:2.3:a:redhat:decision_manager:7.3.1:*:*:*:*:*:*:*n/an/a7.3.1
cpe:2.3:a:fasterxml:jackson-databind:*:*:*:*:*:*:*:*2.0.0 (including)2.6.7.3*

External Links